Fragile Giants: Understanding the Susceptibility of Models to Subpopulation Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gupta, Isha, Lycklama, Hidde, Opel, Emanuel, Rose, Evan, Hithnawi, Anwar
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909345751498752
author Gupta, Isha
Lycklama, Hidde
Opel, Emanuel
Rose, Evan
Hithnawi, Anwar
author_facet Gupta, Isha
Lycklama, Hidde
Opel, Emanuel
Rose, Evan
Hithnawi, Anwar
contents As machine learning models become increasingly complex, concerns about their robustness and trustworthiness have become more pressing. A critical vulnerability of these models is data poisoning attacks, where adversaries deliberately alter training data to degrade model performance. One particularly stealthy form of these attacks is subpopulation poisoning, which targets distinct subgroups within a dataset while leaving overall performance largely intact. The ability of these attacks to generalize within subpopulations poses a significant risk in real-world settings, as they can be exploited to harm marginalized or underrepresented groups within the dataset. In this work, we investigate how model complexity influences susceptibility to subpopulation poisoning attacks. We introduce a theoretical framework that explains how overparameterized models, due to their large capacity, can inadvertently memorize and misclassify targeted subpopulations. To validate our theory, we conduct extensive experiments on large-scale image and text datasets using popular model architectures. Our results show a clear trend: models with more parameters are significantly more vulnerable to subpopulation poisoning. Moreover, we find that attacks on smaller, human-interpretable subgroups often go undetected by these models. These results highlight the need to develop defenses that specifically address subpopulation vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2410_08872
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Fragile Giants: Understanding the Susceptibility of Models to Subpopulation Attacks
Gupta, Isha
Lycklama, Hidde
Opel, Emanuel
Rose, Evan
Hithnawi, Anwar
Machine Learning
As machine learning models become increasingly complex, concerns about their robustness and trustworthiness have become more pressing. A critical vulnerability of these models is data poisoning attacks, where adversaries deliberately alter training data to degrade model performance. One particularly stealthy form of these attacks is subpopulation poisoning, which targets distinct subgroups within a dataset while leaving overall performance largely intact. The ability of these attacks to generalize within subpopulations poses a significant risk in real-world settings, as they can be exploited to harm marginalized or underrepresented groups within the dataset. In this work, we investigate how model complexity influences susceptibility to subpopulation poisoning attacks. We introduce a theoretical framework that explains how overparameterized models, due to their large capacity, can inadvertently memorize and misclassify targeted subpopulations. To validate our theory, we conduct extensive experiments on large-scale image and text datasets using popular model architectures. Our results show a clear trend: models with more parameters are significantly more vulnerable to subpopulation poisoning. Moreover, we find that attacks on smaller, human-interpretable subgroups often go undetected by these models. These results highlight the need to develop defenses that specifically address subpopulation vulnerabilities.
title Fragile Giants: Understanding the Susceptibility of Models to Subpopulation Attacks
topic Machine Learning
url https://arxiv.org/abs/2410.08872